Who we are

KNOC is operated by the team behind the KNOC product (referred to here as "we", "us", or "KNOC"). Our service connects a person who scans a QR code at a door (the "visitor") with the person who owns or manages that door (the "owner").

If you have privacy questions or want to exercise the rights described below, you can reach us at the contact address at the bottom of this page.

What we collect

We try to collect only what the service genuinely needs. There are three categories of data:

How we use it

We use this data to deliver the doorbell experience: showing the visitor's message to the owner, letting the owner reply, sending push notifications, enforcing service hours and quiet hours, and protecting against abuse.

We do not sell personal information. We do not use visitor submissions to train machine-learning models. We do not share owner contact details with visitors or with each other.

Sensitive data

KNOC collects information that is treated as sensitive personal information under several privacy laws โ€” for example, audio recordings, photos that include faces, and approximate location. We treat this data with extra care: it is encrypted in transit, scoped to the people who need to see it (the owner of the door it was sent to, and the operations team for support and abuse review), and is automatically removed at the end of the retention window for your plan.

If you live in a jurisdiction that gives you the right to opt out of the "sale" or "sharing" of sensitive information, you can exercise that right by contacting us. We do not sell or share sensitive information for cross-context advertising.

Live audio calls

Some doors offer a live audio call over the internet, an Early Access feature. While a call is connected, microphone audio travels in real time between the visitor's browser and the owner's device.

KNOC does not record or store live-call audio. There is no live-call recording feature and no stored live-call audio file. This is different from voice notes, which a visitor or owner deliberately records and sends, and which we do store โ€” those are covered under "What we collect" above.

What we keep about a call is metadata: which door and account it belonged to, the identifiers used to route it, when it was requested, rang, was answered and ended, the outcome (answered, declined, missed, expired, and similar), and the ring and length limits that applied. Call metadata is retained separately from visitor submissions and is not subject to the 7-day or 90-day submission window. We use it to operate, secure, troubleshoot, and protect the service from abuse, and may retain it when required by law. We keep short technical logs for the same purposes. We do not keep call content.

To connect a call, the two devices exchange connection details ("signalling") through our realtime service, which passes those messages along and never carries or stores the audio itself. Wherever possible the audio then travels directly between the two devices. Finding that direct path uses a public STUN service operated by Google. If a direct connection cannot be established โ€” typically behind a restrictive network โ€” a relay service may forward the encrypted media between participants on our behalf.

On iPhone, an incoming call is delivered through Apple's Push Notification service as a VoIP push, so it can ring even when the app is closed. The push carries limited routing and display information, including call and door identifiers and a caller label built from the visitor's name and door name. Ordinary, non-call notifications are delivered through Firebase Cloud Messaging.

Service providers we share data with

We use a small number of vetted service providers to run the service. They process data only on our behalf and only for the purposes listed:

How long we keep data

Visitor submissions are kept for a window that depends on the door owner's plan: seven days on the free tier, ninety days on paid plans. The window is set when the knock arrives, so changing plans doesn't extend or shorten knocks that already exist. When the window ends, a daily job deletes the submission along with its photo and audio files.

Call records are not part of this window; they are kept as described under "Live audio calls" above. Records we keep to investigate abuse and protect the security of the service are also kept separately from this window, for those purposes.

We may retain specific records longer when required by applicable law, or for short fraud-prevention purposes.

When you delete your owner account, we deactivate it immediately and schedule it for permanent deletion after a 30-day grace period. Deletion runs automatically after that point, but it is not instantaneous: it may be delayed while we complete billing reconciliation, retry a step that failed, preserve records needed for an abuse or security investigation, or retain a specific record the law requires us to keep.

Your rights

Depending on where you live, you may have the right to: access the personal information we hold about you, correct inaccurate data, delete your data, restrict or object to certain processing, receive a portable copy of your data, and opt out of any "sale" or "sharing" of your information (we do not engage in either).

Owners can exercise most of these rights directly inside the app โ€” the Settings page lets you update your details, change your preferences, and schedule the deletion of your account. Visitors can request the same rights by contacting us with the door slug and an approximate timestamp of their submission so we can find the right record.

Children

KNOC is not directed at children. We do not knowingly collect personal information from children under 13 (or the equivalent age in your country). If you believe a child has submitted personal information through KNOC, please contact us and we will delete the record.

International data transfers

Depending on your country and the cloud regions our service providers use, your data may be processed in a country other than your own. Where required by local law, we use contractual safeguards to protect data during these transfers.

How we protect your data

We use industry-standard practices: encryption in transit, encryption at rest where supported by our storage providers, scoped access controls inside the app, short-lived signed URLs for media files, and operational monitoring. No system is perfectly secure, and we will notify affected users in line with applicable law if a breach poses a real risk to them.

Changes to this policy

We may update this policy as the service evolves or as the law changes. The "Last updated" date at the bottom of this page reflects the most recent revision. Material changes will be highlighted on the homepage or in the app for a reasonable period before they take effect.

Contact

You can contact us about privacy at hello@knoc.app. Please include enough detail for us to identify your record (for owners: the email tied to your account; for visitors: the door slug and an approximate timestamp).

Last updated 2026-08-01.